Kavvo Connect Privacy Policy

Last Updated: August 30, 2026

Effective Date: August 30, 2026

Common Technology (comprising Common Technology Singapore, Shenzhen Common Technology LTD., Common Technology France, and other affiliates) (hereinafter referred to as "Common Technology," "we," "us," or "our") understands the importance of personal data to you. We will protect your personal data and privacy in accordance with applicable laws and regulations. This Privacy Policy (hereinafter referred to as "this Policy") will help you understand the following:

How We Collect and Use Your Personal Data

How We Store and Protect Your Personal Data

How We Share, Transfer, and Publicly Disclose Your Personal Data

How You Manage Your Personal Data

How We Handle Minors' Personal Data

How This Policy Is Updated

How to Contact Us

Please read and understand this Policy carefully before using Kavvo Connect and related services so that you can make informed choices.

This Policy applies to Kavvo Connect (hereinafter referred to as the "App" or "we"), which is provided by Common Technology. Kavvo is a smart wearable device brand under Common Technology, and Kavvo Connect is the official application designed to work with Kavvo-branded smart bands, smart watches, smart earphones, and other devices.

For the purposes of this Policy, Common Technology Singapore serves as the ultimate global data controller, bearing final data controller responsibility for personal data collected and processed through the App worldwide. For users in the People's Republic of China (excluding Hong Kong, Macau, and Taiwan for the purposes of this Policy), Shenzhen Common Technology LTD. serves as the direct data controller. For users in the European Economic Area (EEA), Common Technology France serves as the direct data controller.

1. How We Collect and Use Your Personal Data

Personal data refers to any information recorded electronically or otherwise that can, alone or in combination with other information, identify a specific natural person or reflect the activities of a specific natural person. We collect your personal data primarily to enable you to use the core functions of the App and to ensure the proper operation of the device and application.

We will only collect and use your personal data for the purposes described in this Policy, and we specify the legal basis for each collection activity:

(1) Providing Account Services

1. Account Login

When you use the App, you may choose to log in via a third-party platform account (currently supporting WeChat, Apple ID, and Google Account). After login, we will obtain the public information associated with your third-party account (such as unique account identifier, profile picture, and nickname) to create your account within the App.

Legal Basis: Contractual Necessity. If you do not provide the above information, you will not be able to complete account login and use the core functions of the App.

2. Account Deletion

You may delete your account via the path "Profile > Settings > Account & Security > Delete Account" within the App. After your account is deleted, we will cease to provide you with products or services and will delete or anonymize your personal data in accordance with the requirements of applicable law. Once your account is deleted, your account information cannot be recovered. Please proceed with caution.

(2) Providing Device Connection and Management Services

1. Device Binding and Connection

When you bind and manage Kavvo-branded smart bands, smart watches, smart earphones, and other devices through the App, we need to collect:

Bluetooth Information: Used to search for, pair with, and connect to your device.

Device Information: Including device model, device serial number, firmware version, and device name, used to identify the device and provide compatible services.

Legal Basis: Contractual Necessity. If you do not provide the above information, you will not be able to bind and use your smart device.

2. Device Data Synchronization

Once you have bound your device, we will synchronize data collected by the device to the App for you to view and manage. This data may include:

Health Data: Heart rate, blood oxygen saturation, sleep duration and quality, steps, exercise distance, calories burned, exercise type and duration, weight, height, body fat percentage, body age, and similar metrics.

Exercise Data: Exercise route (GPS location data), exercise speed, exercise pace, etc.

Legal Basis: Your Explicit Consent. Health data constitutes special category data (sensitive personal data). We will separately prompt you via a pop-up notice when you first use the relevant function, and will only begin collection after obtaining your explicit consent. You may disable data synchronization or withdraw your consent at any time in the device settings or app settings; however, withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.

3. Message Notifications and Incoming Call Alerts

When you enable message notifications, incoming call alerts, and similar functions, we need to access:

Notification Permission: Used to push incoming calls, SMS messages, and app notifications from your phone to your device.

Contacts Permission: Used to display the name of incoming callers on your device.

SMS Permission: Used to display SMS message content on your device.

Call Log Permission: Used to display incoming call information on your device.

Legal Basis: Your Explicit Consent. The above permissions are all optional features. You may disable the corresponding permissions at any time in your phone's system settings. Not enabling these permissions will not affect your ability to use other functions of the App.

4. Bluetooth Shutter (Camera Control)

When you use your device as a Bluetooth shutter to remotely control your phone's camera for taking photos or recording videos, we need to access:

Camera Permission: Used to receive photo/video capture commands from your device.

Legal Basis: Your Explicit Consent. This is an optional feature. You may disable the camera permission in your phone's system settings.

5. Firmware Upgrade (OTA)

When you update your device firmware, we need to use the following permissions:

App Installation Permission: Used to download and install device firmware update packages.

Device Information: Used to determine the current firmware version of your device and provide compatible update packages.

Legal Basis: Contractual Necessity and Legitimate Interests. Firmware upgrades are designed to ensure device security, fix known issues, and improve product experience, and are necessary measures to maintain the proper operation of the service.

6. Alarm and Schedule Reminders

When you set device alarms or schedule reminders, we need to access your storage permission to store alarm configuration files.

Legal Basis: Contractual Necessity.

(3) Providing Data Analytics and Product Improvement Services

1. Data Statistics and Analytics

We may collect your usage data (including frequency of app feature usage, device connection duration, crash logs, etc.) to analyze user population characteristics and improve product and service quality. We will de-identify or anonymize the above data so that it cannot be used to re-identify a specific individual.

Legal Basis: Legitimate Interests. We process the above data based on our legitimate interests in improving our products and services, and we ensure that such processing does not unduly affect your rights and freedoms. You may opt out via the path "Profile > Settings > Privacy Settings > Usage Data Collection" within the App.

2. User Experience Improvement Program

We may invite you to participate in our User Experience Improvement Program, which is entirely voluntary. If you participate, we will collect data such as your usage habits and preference settings to optimize product design.

Legal Basis: Your Consent.

(4) Collection and Use in Accordance with Law

Under the following circumstances, we may collect and use your personal data without your consent:

Where it is directly related to national security or national defense;

Where it is directly related to public safety, public health, or major public interests;

Where it is directly related to criminal investigation, prosecution, trial, or enforcement of judgments;

Where it is necessary to protect the life, property, or other significant legitimate rights and interests of you or other individuals, and obtaining consent is difficult;

Where the personal data is disclosed by you to the public at your own discretion;

Where the personal data is collected from lawfully and publicly disclosed information, such as lawful news reports, government information disclosure, and other channels;

Where it is necessary for the conclusion and performance of a contract at your request;

Where it is necessary to maintain the safe and stable operation of the products or services provided, such as detecting and resolving product or service malfunctions;

Other circumstances as provided by applicable laws and regulations.

(5) Summary of Device Permission Requests

To enable the relevant functions of the App, we may request or use certain operating system permissions. The following is a summary of permission requests:

PermissionPurpose / ScenarioCan Be Disabled
BluetoothSearch for, connect to, and manage smart devicesYes (but device connection will be unavailable)
LocationRecord exercise routes (only when exercise mode is active)Yes
CameraBluetooth shutter remote photo/video captureYes
ContactsDisplay incoming caller names on deviceYes
SMSDisplay SMS content on deviceYes
Call LogDisplay incoming call information on deviceYes
StorageStore alarm configurations and cache dataYes
Body SensorsObtain heart rate and other health dataYes (but health data sync will be unavailable)
NotificationsPush notifications to deviceYes
Nearby DevicesDiscover and connect to nearby smart devicesYes (but device discovery will be affected)
App InstallationOTA firmware upgradeYes (but firmware updates will be unavailable)
Network / Wi-FiData transmission and account loginYes (but network-dependent features will be unavailable)

You can manage these permissions in your phone's system settings. Disabling permissions will prevent the corresponding functions from being available but will not affect the use of other functions.

2. How We Store and Protect Your Personal Data

(1) Storage Location

We maintain data centers in multiple countries and regions around the world to provide stable and responsive services. In accordance with the laws and regulations of your country or region, we adhere to the principle of data localization:

Personal data of users in China is stored in data centers within the People's Republic of China;

Personal data of users in the United States and Latin America is stored in data centers in the United States;

Personal data of users in the European Economic Area (EEA), the Middle East, and Africa is stored in data centers in Germany;

Personal data of users in the Asia-Pacific region (including Japan, South Korea, Southeast Asia, etc.) is stored in data centers in Singapore;

Personal data of users in Russia is stored in data centers in Russia;

Personal data of users in India is stored in data centers in India.

(2) Retention Period

We will retain your personal data only for the period necessary to fulfill the purposes described in this Policy and as required by applicable laws and regulations. After the retention period expires, we will delete or anonymize your personal data. However, we may extend the retention period under the following circumstances:

To comply with applicable laws and regulations;

To comply with court judgments, rulings, or other legal procedure requirements;

To comply with requirements of relevant government authorities or legally authorized bodies;

Where reasonably necessary to enforce relevant service agreements or this Policy, safeguard public interests, or protect the personal and property safety or other legitimate rights and interests of our customers, us, our affiliates, other users, or employees.

(3) Security Measures

We have implemented industry-standard security measures to protect the personal data you provide against unauthorized access, public disclosure, use, modification, damage, or loss. We will take all reasonably practicable measures to protect your personal data.

We will take all reasonably practicable measures to ensure that irrelevant personal data is not collected. We will retain your personal data only for the period necessary to fulfill the purposes described in this Policy, unless extended retention is required or permitted by law.

The internet environment is not 100% secure. We will use our best efforts to ensure the security of any information you send to us. If our physical, technical, or administrative safeguards are breached, resulting in unauthorized access, public disclosure, alteration, or destruction of information, and causing damage to your legitimate rights and interests, we will bear corresponding legal liability.

In the unfortunate event of a personal data security incident, we will promptly inform you, in accordance with legal and regulatory requirements, of: the basic facts and potential impact of the incident; the measures we have taken or will take to address it; recommendations for you to independently prevent and mitigate risks; and remedial measures available to you. We will promptly inform you of the relevant circumstances via email, mail, telephone, push notification, or other means. Where it is difficult to notify each data subject individually, we will issue a public announcement in a reasonable and effective manner. At the same time, we will proactively report the handling of personal data security incidents to regulatory authorities as required.

3. How We Share, Transfer, and Publicly Disclose Your Personal Data

(1) Sharing

We will not share your personal data with any company, organization, or individual outside of Common Technology, except in the following circumstances:

Sharing with Your Explicit Consent: We will share your personal data with other parties after obtaining your explicit consent.

Sharing with Authorized Partners: We may engage authorized partners to provide certain services on your behalf or to perform functions on our behalf. We will only share your data for the lawful, legitimate, necessary, specific, and explicit purposes stated in this Policy. Authorized partners will only have access to the information necessary to perform their duties and may not use such information for any other purpose. Currently, our authorized partners include the following categories:

Third-Party Login Service Providers: WeChat (Tencent), Apple, and Google. When you log in using any of these third-party accounts, we will engage in necessary information exchange with the relevant third party.

Data Analytics Service Providers: We may use third-party analytics tools (such as Google Analytics, Firebase, etc.) to help us understand user usage patterns and improve our products. The data collected by these tools is de-identified or anonymized.

Cloud Service Providers: We use globally distributed cloud services to store data. The selection of service providers depends on your region (e.g., Alibaba Cloud / Tencent Cloud in China, AWS in the United States, Azure in Europe, etc.).

Sharing with Affiliates: Your personal data may be shared with affiliated companies under Common Technology (comprising Common Technology Singapore, Shenzhen Common Technology LTD., Common Technology France, and other affiliates). We will only share the necessary personal data, and such sharing will be subject to the purposes stated in this Policy. If an affiliate wishes to change the purpose of processing personal data, it will seek your authorized consent again.

Sharing under Legal Circumstances: We may share your personal data externally as required by applicable laws and regulations, for the purpose of resolving litigation disputes, or as required by administrative or judicial authorities in accordance with the law.

(2) Transfer

We will not transfer your personal data to any company, organization, or individual, except in the following circumstances:

Transfer with your explicit consent: After obtaining your explicit consent, we will transfer your personal data to another party;

In the event of a merger, acquisition, or bankruptcy liquidation involving a transfer of personal data, we will require the new company or organization holding your personal data to continue to be bound by this Policy; otherwise, we will require such company or organization to seek your authorized consent anew.

(3) Public Disclosure

We will publicly disclose your personal data only under the following circumstances:

After obtaining your explicit consent;

Legal Disclosure: We may publicly disclose your personal data where required by law, legal proceedings, litigation, or mandatory requirements of government authorities.

4. How You Manage Your Personal Data

In accordance with applicable laws and regulations, we guarantee the following rights for you with respect to your personal data:

(1) Access and Correction of Your Personal Data

You may access your personal data (such as profile picture, nickname, health data, exercise data, etc.) through the "Profile" page of the App. If you need to correct or supplement your data, you may do so directly on the corresponding page.

(2) Deletion of Your Personal Data

You may request that we delete your personal data under the following circumstances:

Where our processing of personal data violates applicable laws and regulations;

Where we collected or used your personal data without obtaining your consent;

Where our processing of personal data violates our agreement with you;

Where you no longer use our products or services, or you have deleted your account;

Where we no longer provide products or services to you.

You may submit a deletion request through in-app feedback or by sending an email to privacy@kavvo.com.

(3) Withdrawal of Your Consent

You may withdraw your consent in the following ways:

Disabling the permissions you previously granted in your phone's system settings;

Managing your privacy preferences via "Profile > Settings > Privacy Settings" within the App;

For health data collection, disabling data synchronization in your device settings.

After you withdraw your consent, we will cease processing the corresponding personal data. However, your decision to withdraw consent will not affect the lawfulness of processing carried out based on your prior authorization.

(4) Deletion of Your Account

You may delete your account via the path "Profile > Settings > Account & Security > Delete Account" within the App. After your account is deleted, we will cease to provide you with products or services and will delete or anonymize your personal data in accordance with the requirements of applicable law.

(5) Obtaining a Copy of Your Personal Data

You have the right to obtain a copy of your personal data. You may request to export your data via the path "Profile > Settings > Privacy Settings > Export Data" within the App. If this function is not yet available, you may submit a request by contacting our privacy department.

(6) Responding to Your Requests

For security purposes, we may require you to submit a written request or otherwise verify your identity. We will respond within 30 days of receiving your request and verifying your identity.

In principle, we do not charge a fee for reasonable requests. However, for repeated or excessive requests, we may charge a cost-based fee as appropriate. We may decline requests that are manifestly unfounded, excessive, require disproportionate technical measures, pose a risk to the legitimate rights and interests of others, or are highly impractical.

5. How We Handle Minors' Personal Data

Our products and services are primarily intended for adults. We do not knowingly collect personal data from minors.

In accordance with the laws and regulations of different countries and regions, our definition of minors and corresponding protective measures are as follows:

China: Users under the age of 14 are considered children. Guardians of children should carefully read this Policy and the Children's Privacy Notice, and help children use our products or services only after obtaining the guardian's explicit consent.

United States: Users under the age of 13 are considered children (pursuant to COPPA). We do not knowingly collect personal data from children under 13 without obtaining verifiable parental consent.

European Economic Area (EEA) : The age threshold for children is determined by the laws of each Member State (typically between 13 and 16 years of age). We process children's personal data in accordance with the GDPR and relevant Member State laws, and only with parental authorization or consent.

Other Regions: Corresponding protective measures are implemented in accordance with the age thresholds defined by local laws.

If you are a guardian of a child and have questions regarding the personal data of the child under your guardianship, please contact us using the contact information provided in this Policy.

If we discover that we have collected personal data from a child without verifiable parental consent, we will take steps to delete such data as soon as possible.

6. How This Policy Is Updated

We may revise this Policy from time to time. When the terms of this Policy change, we will notify you of the updated Policy in an appropriate manner at the time of the version update, and will seek your consent again.

We will not reduce the rights you are entitled to under this Policy without your explicit consent.

For material changes, we will provide more prominent notice (including but not limited to in-app pop-ups, push notifications, email, and other means).

Material changes referred to in this Policy include but are not limited to:

Material changes in our service model, such as changes in the purposes of processing personal data, the types of personal data processed, the methods of using personal data, etc.;

Material changes in our ownership structure, organizational structure, etc., such as changes in ownership due to business adjustments, bankruptcy, mergers, or acquisitions;

Changes in the primary recipients of shared, transferred, or publicly disclosed personal data;

Material changes in your rights with respect to personal data processing and how such rights are exercised;

Changes in the department responsible for personal data security, contact information, and complaint channels;

Where a personal data security impact assessment report indicates a high risk.

7. How to Contact Us

Ultimate Global Data Controller: Common Technology Singapore

Direct Data Controller for China: Shenzhen Common Technology LTD.

Direct Data Controller for the European Economic Area (EEA): Common Technology France

If you have any questions, comments, or suggestions regarding this Policy, or if you wish to exercise your personal data rights, please contact us via:

Email: privacy@kavvo.com

We will respond to your inquiry within 30 days of receipt.

If you are dissatisfied with our response, particularly if you believe that our processing of personal data has infringed upon your legitimate rights and interests, you may also file a complaint or report with the data protection supervisory authority in your country or region, or bring a lawsuit before a court of competent jurisdiction.

Supplemental Children's Privacy Notice

Common Technology (comprising Common Technology Singapore, Shenzhen Common Technology LTD., Common Technology France, and other affiliates) (hereinafter referred to as "we," "us," or "our") understands the importance of children's personal data and privacy. This Supplemental Children's Privacy Notice is intended to explain to guardians (hereinafter referred to as "you") and the children under your guardianship (referring to minors under the age of 14, hereinafter referred to as "children") how we collect, use, store, and process children's personal data.

This Notice primarily applies to children under the age of 14 in China. For other regions, please refer to the differentiated provisions in Section 5 of this Policy.

If you are a child, please ensure that your guardian reads this Notice together with you, and have your guardian help you use our products or services only after obtaining your guardian's consent.

1. How We Collect and Use Children's Personal Data

When a child uses Kavvo Connect and related services, we will only collect the minimum personal data necessary to fulfill the service functions, and only after obtaining the guardian's explicit consent.

The types of children's personal data we collect are limited to:

Account Information: When a child logs in via a third-party account (WeChat, Apple ID, or Google Account), we obtain the public information associated with that third-party account (such as unique account identifier, profile picture, and nickname).

Device Data: When a child uses a Kavvo smart device, the device collects health data (heart rate, blood oxygen, sleep, steps, etc.) and exercise data.

How we use this information:

To provide the child with device connection, data synchronization, and display services;

To help the guardian understand the child's activity and health status.

2. Obtaining Guardian Consent

Before collecting and using children's personal data, we will obtain the guardian's explicit consent through the following means:

When a child first uses the App, a pop-up notice will prompt the guardian to read and agree to this Notice;

The guardian may explicitly indicate consent by checking "Agree" or similar means.

3. Storage and Protection of Children's Personal Data

We strictly comply with applicable laws and regulations and implement stricter protective measures for children's personal data:

Children's personal data is stored in accordance with the data localization principles described in Section 2 of this Policy;

We employ encryption, access control, and other technical measures to protect the security of children's personal data;

We have established access restrictions for children's personal data, granting access only to authorized personnel.

4. Sharing of Children's Personal Data

We will not share children's personal data with third parties except:

With the guardian's explicit consent;

Where required by applicable laws and regulations or mandatory requirements of government authorities.

5. Guardian's Rights

As a guardian, you have the following rights:

Access: You may request to access the children's personal data we have collected;

Correction: If you discover that any children's personal data is inaccurate, you may request a correction;

Deletion: You may request that we delete the children's personal data we have collected;

Withdrawal of Consent: You may withdraw your consent to our collection and use of children's personal data at any time.

You may exercise the above rights by contacting us using the contact information provided in Section 7 of this Policy.

6. Updates to This Notice

We may update this Notice from time to time. The updated Notice will be prominently displayed within the App, and we will seek your consent again.